From 0317ced63af1f730f1c0a5bd1e4aedd9a3a27ba8 Mon Sep 17 00:00:00 2001 From: evazion Date: Tue, 1 Nov 2022 18:01:12 -0500 Subject: [PATCH] media assets: fix unsafe redirect error in /media_assets/:id/:variant Fix error when redirecting to image hosted on separate domain. --- app/controllers/media_assets_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/media_assets_controller.rb b/app/controllers/media_assets_controller.rb index 2f668e457..6beb3a5b0 100644 --- a/app/controllers/media_assets_controller.rb +++ b/app/controllers/media_assets_controller.rb @@ -41,6 +41,6 @@ class MediaAssetsController < ApplicationController variant = media_asset.variant(params[:variant]) raise ActiveRecord::RecordNotFound if variant.nil? - redirect_to variant.file_url + redirect_to variant.file_url, allow_other_host: true end end